This tip was submitted to the SearchWin2000.com Tip Exchange by member Carol Miller. Let other users know how useful it is by rating the tip below.
Services are known to, and exploited by, hackers with even only a basic understanding of Active Directory, DNS, and WINS. Compromising these accounts opens a broad based security issue.
To better control services, use an account that has been specially created to start these services and place the user account in a special OU. The OU can then be secured with a Group Policy that pertains to these accounts alone. This works for system service accounts as well as for back office products such as Exchange and SQL that require service accounts to log into the network.